Mautic Projects Component Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored Cross-Site Scripting (XSS) vulnerability has been identified in the Projects component of Mautic version 7. This issue arises because user-supplied project names are displayed without adequate sanitization in administrative detail views, such as campaigns, emails, or forms. An authenticated user with the ability to create or edit projects can exploit this vulnerability by injecting malicious script payloads. When an administrative user interacts with an entity linked to the compromised project, the injected script executes in their browser session. This could enable the attacker to perform actions on behalf of the victim, modify system settings, or steal sensitive information.

Impact

Exploitation of this vulnerability allows for stored Cross-Site Scripting, where injected scripts are executed in the context of the user viewing the affected project. This could lead to unauthorized administrative actions, changes in system configurations, or exfiltration of confidential data.

Remediation

Users can upgrade to Mautic version 7.1.2 to address this vulnerability. For those using earlier versions of Mautic 7, it is recommended to restrict project creation and editing permissions to trusted administrative users.

Added: May 29, 2026, 12:18 PM
Updated: May 29, 2026, 12:18 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
5.4
exploitability
5.2
remediation
7.9
relevance
9.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.